Pin caller-auth digest in warn on independently rollable overlay pins
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

The sanctioned Helm chart could not promote ADR 0004 at all, and the
emergency manifests selected enforce. That made a FLEX-WP-0011 apply
either a no-op or a global 401. First production pin is now warn, per
consumer, on CI digest sha256:138aa347… . Enforce stays a later
per-consumer flip so USER-WP-0023-T03 can close without waiting on
tenant-engine.
This commit is contained in:
tegwick 2026-08-19 12:31:08 +02:00
parent 3de72fe6f5
commit fa278674c1
22 changed files with 268 additions and 55 deletions

View file

@ -18,3 +18,18 @@ app.kubernetes.io/name: {{ include "flex-auth.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/part-of: flex-auth
{{- end -}}
{{- define "flex-auth.callerAuth.mode" -}}
{{- $mode := "disabled" -}}
{{- if and (hasKey .Values "callerAuth") .Values.callerAuth (hasKey .Values.callerAuth "mode") .Values.callerAuth.mode -}}
{{- $mode = .Values.callerAuth.mode -}}
{{- end -}}
{{- if not (has $mode (list "disabled" "warn" "enforce")) -}}
{{- fail (printf "callerAuth.mode must be disabled, warn, or enforce; got %q" $mode) -}}
{{- end -}}
{{- $mode -}}
{{- end -}}
{{- define "flex-auth.callerAuth.enabled" -}}
{{- if has (include "flex-auth.callerAuth.mode" .) (list "warn" "enforce") -}}true{{- else -}}false{{- end -}}
{{- end -}}